RubySec

Providing security resources for the Ruby community

OSVDB-97854 (fog-dragonfly): Dragonfly Gem for Ruby on Windows Shell Escaping Weakness

Dragonfly Gem for Ruby on Windows Shell Escaping Weakness

Published: September 01, 2011

SECURITY IDENTIFIERS

GEM

fog-dragonfly

PATCHED VERSIONS

>= 0.9.6

DESCRIPTION

Dragonfly Gem for Ruby contains a flaw that is due to the program failing to properly escape a shell that contains injected characters. This may allow a context-dependent attacker to potentially execute arbitrary commands.

This gem has been renamed. Please use "dragonfly" from now on.

RELATED